China’s cyberspace regulator has released a draft rule for “large personal-information processors,” consolidating two earlier platform-focused drafts into one accountability regime for the biggest data holders.国家网信部门发布《大型个人信息处理者个人信息保护规定(征求意见稿)》,将早前两份聚焦平台的规定整合为面向最大规模数据处理者的统一责任制度。 A processor handling over 10 million individuals’ personal information, or meeting other significance tests, … China’s Draft Rule for Large Personal-Information Processors: What Foreign-Invested Platforms and Apps Need to KnowRead more
PIPL Compliance
China’s amended Cybersecurity Law in force from 1 January 2026: AI clauses, tenfold penalties and wider extraterritorial reach
The Decision amending the Cybersecurity Law was adopted on 28 October 2025 and takes effect on 1 January 2026, with 14 amendments and a reissued text. 修改《网络安全法》的决定于2025年10月28日通过、2026年1月1日起施行,共14项修改并重新公布。 A new Article 20 builds the first basic-law “development plus oversight” framework for … China’s amended Cybersecurity Law in force from 1 January 2026: AI clauses, tenfold penalties and wider extraterritorial reachRead more
China’s Network Data Security Regulation: what foreign-invested firms must do
China’s Network Data Security Regulation (State Council Order 790) took effect on 1 January 2025, turning the Cybersecurity Law, Data Security Law and PIPL into operational, enforceable obligations for every network data processor — including foreign-invested firms. 《网络数据安全管理条例》(国务院令790号)自 2025 年 … China’s Network Data Security Regulation: what foreign-invested firms must doRead more
Cross-Border Transfer of Personal Information via the China Standard Contract: Thresholds, Filing and Model Clauses
The standard contract is the second of PIPL’s three export routes: sign with the overseas recipient, then file with the provincial cyberspace administration. 标准合同是《个保法》三条出境路径中的第二条:与境外接收方签约,再向省级网信部门备案。 Eligibility is fixed by volume bands: non-CIIO, 100k–under 1m non-sensitive or under 10k sensitive individuals, and … Cross-Border Transfer of Personal Information via the China Standard Contract: Thresholds, Filing and Model ClausesRead more
China’s Personal Information Export Certification: The Third Route Opens on 1 January 2026
China’s third data-export route opened on 1 January 2026 under CAC and SAMR Order No. 20. 第20号令使个人信息保护认证成为可用通道,2026年1月1日起施行。 Eligibility is narrow: non-CIIO handlers, 100,000 to under 1m individuals’ non-sensitive data or under 10,000 individuals’ sensitive data, and no important data. 适用面窄:非CIIO主体,10万至不满100万人非敏感或不满1万人敏感个人信息,且不含重要数据。 … China’s Personal Information Export Certification: The Third Route Opens on 1 January 2026Read more
PIPL Compliance for Foreign Companies
PIPL took effect on 1 November 2021 and has extraterritorial reach, binding overseas processors that handle personal information of individuals in China. 《个人信息保护法》于2021年11月1日施行,并具有域外效力(第三条),约束处理中国境内自然人个人信息的境外处理者。 Processing requires a documented lawful basis under Article 13; consent is prominent but not the only one, … PIPL Compliance for Foreign CompaniesRead more
Personal Information Compliance and Cross-Border Data for Foreign Firms: The 2026 Simplification and the Three Outbound Paths
The Personal Information Protection Law gives three cross-border paths — security assessment, standard contract, and certification — all now operable after the 2026 Certification Measures took effect on 1 January 2026.《个人信息保护法》确立安全评估、标准合同、认证三条出境路径;随2026年《个人信息出境认证办法》1月1日施行,三者均已可操作。 A July 2026 rule simplifies compliance for “small” processors … Personal Information Compliance and Cross-Border Data for Foreign Firms: The 2026 Simplification and the Three Outbound PathsRead more
Cross-Border HR Data and PIPIA: Personal Information Compliance for Expatriate Workforces
Cross-border transfers of employee personal information are exempt from the security-assessment, standard-contract and certification routes where they implement cross-border HR management under a duly adopted labour rule or collective contract. 按照依法制定的劳动规章制度和依法签订的集体合同实施跨境人力资源管理的员工个人信息出境,可免予安全评估、标准合同与认证。 A Personal Information Protection Impact Assessment (PIPIA) is still … Cross-Border HR Data and PIPIA: Personal Information Compliance for Expatriate WorkforcesRead more
Personal Information Protection Officer and the Domestic Institution or Designated Representative for Overseas Processors under China’s PIPL: Governance Roles and Filing Obligations
PIPL creates two distinct governance roles: a personal information protection officer (PIPO) under Article 52, and a domestic dedicated institution or designated representative for overseas processors under Article 53. 《个人信息保护法》设定了两类不同的治理角色:第五十二条项下的个人信息保护负责人(个保负责人),以及第五十三条项下境外处理者须设立的境内专门机构或指定代表。 The 100-million-person threshold is the operative trigger: processors handling over … Personal Information Protection Officer and the Domestic Institution or Designated Representative for Overseas Processors under China’s PIPL: Governance Roles and Filing ObligationsRead more
App personal-information collection compliance in China (2026): the CAC draft rules and what FIEs must do
The CAC’s January 2026 draft “Rules on Personal Information Collection and Use by Internet Applications” codifies consent, separate consent for sensitive data, and minimal collection for apps, SDKs, distribution platforms and device makers. 国家网信办2026年1月《互联网应用程序个人信息收集使用规定(征求意见稿)》将同意、敏感信息单独同意与最小必要等要求成文化,覆盖App、SDK、分发平台与终端厂商。 Sensitive personal information (face, fingerprint, voiceprint) … App personal-information collection compliance in China (2026): the CAC draft rules and what FIEs must doRead more
